Description
--kubelet-certificate-authority specifies the CA file kube-apiserver uses to verify kubelet serving certificates. The API server does not verify those certificates by default, leaving connections over untrusted networks vulnerable to interception.
Potential impact
- Logs or management requests can reach an endpoint impersonating a kubelet.
- An incorrect CA or server name can cause verification failures and interrupt node management.
Remediation
- Set
--kubelet-certificate-authorityto the trusted CA bundle that issued the kubelet serving certificates. - Check that the connection address matches the certificate’s DNS name or IP address and that the API server can read the file.
- Configure kubelet authentication and authorization, then test successful trusted connections and rejection of untrusted certificates.
Examples
These historical arguments use Kubernetes 1.6.0. Substitute the actual CA file and mount path used by your supported deployment.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command: ["kube-apiserver"]
No CA is specified for verifying the kubelet serving certificate. HTTPS encryption alone does not verify the server’s identity.
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command: ["kube-apiserver"]
args: ["--kubelet-certificate-authority=/path/to/any/cert/file.pem"]
A verification CA file is specified. Its contents must actually correspond to the kubelet serving certificate.